Skip to content

Bump AngleSharp and 19 others - #186

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/aspireOpenLdap/Aspire.OpenLdap.Testing/dotnet-and-aspire-638ad28160
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/aspireOpenLdap/Aspire.OpenLdap.Testing/dotnet-and-aspire-638ad28160

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Updated AngleSharp from 1.7.1 to 1.8.3.

Release notes

Sourced from AngleSharp's releases.

1.8.3

Released on Wednesday, September 30 2026

What's Changed

  • Improved cancellation of queued timer callbacks (#​1357) @​PrzemyslawKlys
  • Improved configuration / setup performance (#​1360) @​PrzemyslawKlys
  • Fixed form submission ignoring sandbox restrictions (#​1358) @​PrzemyslawKlys
  • Fixed <base> elements not following frozen document base URL and tree-order mutation rules (#​1355, #​1362)
  • Fixed native Unloading handlers subscribing to unloading instead of beforeunload (#​1354) @​PrzemyslawKlys
  • Added OnReset event to inform script hosts of native listener removals (#​1356) @​PrzemyslawKlys
  • Added pull-based HTML serialization stream (#​1361) @​PrzemyslawKlys
  • Released 1.8.3 by @​FlorianRappl in Release 1.8.3 AngleSharp/AngleSharp#1363

New Contributors

Full Changelog: AngleSharp/AngleSharp@v1.8.2...v1.8.3

1.8.2

Released on Friday, September 18 2026

What's Changed

  • Improved attribute selector serialization to write only the case-sensitivity modifier that was specified (#​1351)
  • Improved id/name lookup on collections (document.forms["x"], form.elements["x"], ...) to enumerate the underlying sequence once instead of twice
  • Improved performance of form.elements / fieldset.elements by walking the tree directly (#​1350)
  • Improved GetElementsByTagName / GetElementsByClassName traversal to stop double-scanning each element's children
  • Improved selector specificity (Selectors.Specificity, ComplexSelector.Specificity) to be computed once instead of recomputed on every read
  • Improved ListSelector.GetMatchingSelector to sort its selectors once instead of on every call
  • Improved performance of HTML tree construction by keeping mutation logic out of it (#​1347)
  • Improved performance of DOM mutations by building a mutation record only when an observer will consume it (#​1347)
  • Improved performance of parser attribute duplication check
  • Fixed Document.Forms allocating a new collection instance per read, contradicting its own [DomSameObject] contract
  • Fixed classList and the other reflected token lists writing their content attribute without running the attribute change steps or queueing a mutation record
  • Fixed clearing a reflected boolean attribute such as disabled removing it without running the attribute change steps or queueing a mutation record
  • Fixed vulnerability via SVG style serialization (GHSA-cgp3-27rh-pcp2)
  • Fixed a StackOverflowException when parsing a document with deeply nested unclosed <template> elements
  • Added Document.MutationVersion, a synchronous counter of DOM mutations that a parse leaves unchanged (#​1344, #​1347)
  • Released 1.8.2 by @​FlorianRappl in Release 1.8.2 AngleSharp/AngleSharp#1353

New Contributors

Full Changelog: AngleSharp/AngleSharp@v1.8.1...v1.8.2

1.8.1

Released on Thursday, September 10 2026

What's Changed

  • Updated DoFocus and DoBlur to apply to form elements
  • Improved explicit form ownership to take precedence over ancestor forms for connected controls (#​1323) @​sebastienros
  • Fixed HTML hyperlink pseudo-classes omitting empty href and matching link elements (#​1337) @​sebastienros
  • Fixed HTML-namespace element creation losing local-name case (#​1327) @​sebastienros
  • Fixed :enabled incorrectly matching HTML links with nonempty href (#​1324) @​sebastienros
  • Fixed changing focus of elements
  • Released 1.8.1 by @​FlorianRappl in Release 1.8.1 AngleSharp/AngleSharp#1343

New Contributors

Full Changelog: AngleSharp/AngleSharp@v1.8.0...v1.8.1

1.8.0

Released on Saturday, September 5 2026

What's Changed

  • Improved AngleSharp's test website
  • Fixed script data escaped state potentially not bouncing back correctly
  • Added the DomSameObject annotation for the respective IDL members (#​1314) @​lahma
  • Added the DomReturnType annotation for methods returning a different IDL type (#​1318)
  • Released 1.8.0 by @​FlorianRappl in Release 1.8.0 AngleSharp/AngleSharp#1317

Full Changelog: AngleSharp/AngleSharp@v1.7.3...v1.8.0

1.7.3

Released on Thursday, September 3 2026

What's Changed

  • Improved tracking of parse exceptions in the HtmlParser (#​1315) @​lahma
  • Fixed tokenizer buffer overrun on encoding change (#​1290) @​jafin
  • Fixed selector text dropping the nth-child of clause (#​1292) @​jafin
  • Fixed selector text dropping the case-insensitive (#​1291) @​jafin
  • Fixed selector specificity carrying between fields instead of saturating (#​1300) @​meziantou
  • Fixed condition check for disposed state in ReturnToPool (#​1296) @​meziantou
  • Fixed ArgumentOutOfRangeException CSS escapes (#​1299) @​meziantou
  • Fixed whitespace around An+B CSS selector notations (#​1297)
  • Fixed unsupported pseudo-classes matching everything (#​1295)
  • Fixed DomException for invalid foreign attribute names such as xml:lang[ (#​1294)
  • Fixed script data escaped state leaving escaped mode too early (#​1298)
  • Fixed CurrentScript not indicating the currently executing script (#​1308) @​lahma
  • Fixed returned missing attribute-properties to use empty string instead of null (#​1313) @​lahma
  • Fixed removal of data-* attributes (#​1310) @​lahma
  • Added missing DomName/DomAccessor annotations (#​1301) @​meziantou
  • Added missing DomLiterals attribute to AdjacentPosition (#​1311) @​lahma
  • Released 1.7.3 by @​FlorianRappl in Release 1.7.3 AngleSharp/AngleSharp#1302

Full Changelog: AngleSharp/AngleSharp@v1.7.2...v1.7.3

1.7.2

Released on Sunday, August 23 2026

What's Changed

  • Fixed matching of annotation-xml encoding to be case-insensitive (#​1284) @​arpitjain099
  • Fixed <xmp> usage in <select> elements
  • Added ability to parse immutable byte buffers without a stream (#​1286) @​dv00d00
  • Released 1.7.2 by @​FlorianRappl in Release 1.7.2 AngleSharp/AngleSharp#1288

New Contributors

Full Changelog: AngleSharp/AngleSharp@1.7.1...v1.7.2

Commits viewable in compare view.

Updated Aspire.AppHost.Sdk from 13.5.3 to 13.6.0.

Release notes

Sourced from Aspire.AppHost.Sdk's releases.

13.6.0

Aspire 13.6.0

Aspire 13.6 brings persistent application history, a refreshed and more interactive dashboard, first-party Java and Rust hosting, and new Azure deployment options. Coordinated .NET builds, portable volume paths, sharper CLI workflows, and more capable editor tooling make it easier to build, debug, and deploy applications across languages.

Highlights

  • 🗃️ Persistent, refreshed dashboard — SQLite-backed telemetry and resource snapshots let you revisit up to ten application runs, with read-only access to completed runs and default retention limits of 100,000 console log messages, structured logs, and traces each. The dashboard now ships as Native AOT and adopts Fluent UI v5 with a collapsible navigation rail.
  • 🖥️ AppHost-owned terminals and database REPLs — Experimental terminal APIs let AppHosts create interactive sessions in a dashboard dock, dialog, or separate window. Opt-in WithRepl() commands open bundled clients for PostgreSQL, MySQL, MongoDB, SQL Server, Redis, and Valkey, while aspire terminal ps and aspire terminal tape play support discovery and repeatable terminal interactions.
  • 🌐 First-party Java and Rust hosting — New Aspire.Hosting.Java and Aspire.Hosting.Rust packages bring Maven, Gradle, Spring Boot, Quarkus, and Cargo applications into the app model, with generated container builds and VS Code debugging. These integrations build on work that originated in the Aspire Community Toolkit.
  • 🛠️ More flexible AppHosts — The prerelease Aspire.Hosting.Dotnet integration coordinates compatible projects into shared restore and build groups and supports .NET SDK container publishing. Portable volume-path environment variables work across local execution and deployment, while TypeScript AppHosts gain standard appsettings.json configuration and Deno runtime support.
  • ⌨️ Sharper CLI workflows — Select launch profiles with aspire run and aspire start, update repository-local CLI manifests with aspire update, create file-based C# AppHosts with aspire init --language csharp --file-based, and export TypeScript API data with aspire sdk export. Terminal commands no longer need a feature flag, Linux certificate trust includes Firefox NSS databases, and aspire stop --force --volumes adds explicit cleanup of Aspire-owned volumes.
  • 💻 More capable VS Code tooling — Coding agents can start and stop AppHosts through the extension, and the Aspire pane exposes deploy, publish, and pipeline actions. Multi-root discovery, worktree-scoped lifecycle operations, preserved launch arguments, clearer debug logs, and missing-debugger guidance make complex workspaces more predictable.
  • ☁️ New Azure options in preview — Azure Connector Namespace models external-service connections and managed MCP server configurations. Azure Container Apps Sandboxes adds isolated sandbox deployments with configurable resource tiers and lifecycle policies, while Azure Container Apps Express offers a simplified environment option for rapid provisioning.
  • ☸️ More expressive, reliable deployments — Experimental Azure Provisioning SDK proxies let polyglot AppHosts customize infrastructure. Deployment state is isolated under ASPIRE_HOME, Kubernetes preserves inherited hostnames and embedded parameter values, and AKS gains persistent-volume provisioning and more reliable cleanup.
  • 🔌 Expanded integrations — Experimental Deno hosting and MongoDB replica sets join Foundry Toolboxes, remote Foundry Local endpoints, Blazor WebAssembly debugging, and configurable Dev Tunnel expiration. Azure Cosmos DB and AI Inference client integrations gain health checks, and the vNext Cosmos DB emulator sends its own telemetry to the dashboard.

⚠️ Breaking changes

Notable changes include automatic TLS for local MongoDB servers when a certificate is available, the Linux-based vNext Cosmos DB emulator becoming the default, new Azure Front Door origin names that can require cleanup of existing origins, portable connection-string environment-variable aliases on stricter deployment targets, and experimental terminal types moving from Aspire.Hosting.Terminals to Aspire.Hosting.ApplicationModel.

See the full list and migration guidance in the Aspire 13.6 breaking changes.

📖 Learn more

For complete details, examples, migration guidance, and everything new in this release, read What's new in Aspire 13.6.

Thank you to all the community contributors who helped make Aspire 13.6 possible! 💜


Full Changelog: v13.5.4...v13.6.0

Full commit: 56f3e9c0d216c0c7069dabb49dd0464e4827744f

13.5.4

What's New in Aspire 13.5.4

Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.

🐛 Fixes

  • 📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #​20091. (#​20094, backport of #​20092, @​davidfowl)

  • 🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #​18790. (#​19853, backport of #​19230, @​Vladipz)

  • ☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the azure-environment resource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #​19617. (#​19998, backport of #​19843, @​eerhardt)

  • 🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to localhost: URLs, preserving the original library files while still configuring the requested ports. Fixes #​20030. (#​20110, backport of #​20031, @​bart-vmware, @​JamesNK)

  • 🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#​20119, backport of #​19965, @​askpt, @​joperezr)

  • 🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic — IAwsRadiusProviderBuilder and IAzureRadiusProviderBuilder are now marked with ASPIRERADIUS003, matching the existing WithAwsProvider and WithAzureProvider methods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#​19874, @​sebastienros)


Full Changelog: v13.5.3...v13.5.4

Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6

Commits viewable in compare view.

Pinned Aspire.Hosting at 13.6.0.

Release notes

Sourced from Aspire.Hosting's releases.

13.6.0

Aspire 13.6.0

Aspire 13.6 brings persistent application history, a refreshed and more interactive dashboard, first-party Java and Rust hosting, and new Azure deployment options. Coordinated .NET builds, portable volume paths, sharper CLI workflows, and more capable editor tooling make it easier to build, debug, and deploy applications across languages.

Highlights

  • 🗃️ Persistent, refreshed dashboard — SQLite-backed telemetry and resource snapshots let you revisit up to ten application runs, with read-only access to completed runs and default retention limits of 100,000 console log messages, structured logs, and traces each. The dashboard now ships as Native AOT and adopts Fluent UI v5 with a collapsible navigation rail.
  • 🖥️ AppHost-owned terminals and database REPLs — Experimental terminal APIs let AppHosts create interactive sessions in a dashboard dock, dialog, or separate window. Opt-in WithRepl() commands open bundled clients for PostgreSQL, MySQL, MongoDB, SQL Server, Redis, and Valkey, while aspire terminal ps and aspire terminal tape play support discovery and repeatable terminal interactions.
  • 🌐 First-party Java and Rust hosting — New Aspire.Hosting.Java and Aspire.Hosting.Rust packages bring Maven, Gradle, Spring Boot, Quarkus, and Cargo applications into the app model, with generated container builds and VS Code debugging. These integrations build on work that originated in the Aspire Community Toolkit.
  • 🛠️ More flexible AppHosts — The prerelease Aspire.Hosting.Dotnet integration coordinates compatible projects into shared restore and build groups and supports .NET SDK container publishing. Portable volume-path environment variables work across local execution and deployment, while TypeScript AppHosts gain standard appsettings.json configuration and Deno runtime support.
  • ⌨️ Sharper CLI workflows — Select launch profiles with aspire run and aspire start, update repository-local CLI manifests with aspire update, create file-based C# AppHosts with aspire init --language csharp --file-based, and export TypeScript API data with aspire sdk export. Terminal commands no longer need a feature flag, Linux certificate trust includes Firefox NSS databases, and aspire stop --force --volumes adds explicit cleanup of Aspire-owned volumes.
  • 💻 More capable VS Code tooling — Coding agents can start and stop AppHosts through the extension, and the Aspire pane exposes deploy, publish, and pipeline actions. Multi-root discovery, worktree-scoped lifecycle operations, preserved launch arguments, clearer debug logs, and missing-debugger guidance make complex workspaces more predictable.
  • ☁️ New Azure options in preview — Azure Connector Namespace models external-service connections and managed MCP server configurations. Azure Container Apps Sandboxes adds isolated sandbox deployments with configurable resource tiers and lifecycle policies, while Azure Container Apps Express offers a simplified environment option for rapid provisioning.
  • ☸️ More expressive, reliable deployments — Experimental Azure Provisioning SDK proxies let polyglot AppHosts customize infrastructure. Deployment state is isolated under ASPIRE_HOME, Kubernetes preserves inherited hostnames and embedded parameter values, and AKS gains persistent-volume provisioning and more reliable cleanup.
  • 🔌 Expanded integrations — Experimental Deno hosting and MongoDB replica sets join Foundry Toolboxes, remote Foundry Local endpoints, Blazor WebAssembly debugging, and configurable Dev Tunnel expiration. Azure Cosmos DB and AI Inference client integrations gain health checks, and the vNext Cosmos DB emulator sends its own telemetry to the dashboard.

⚠️ Breaking changes

Notable changes include automatic TLS for local MongoDB servers when a certificate is available, the Linux-based vNext Cosmos DB emulator becoming the default, new Azure Front Door origin names that can require cleanup of existing origins, portable connection-string environment-variable aliases on stricter deployment targets, and experimental terminal types moving from Aspire.Hosting.Terminals to Aspire.Hosting.ApplicationModel.

See the full list and migration guidance in the Aspire 13.6 breaking changes.

📖 Learn more

For complete details, examples, migration guidance, and everything new in this release, read What's new in Aspire 13.6.

Thank you to all the community contributors who helped make Aspire 13.6 possible! 💜


Full Changelog: v13.5.4...v13.6.0

Full commit: 56f3e9c0d216c0c7069dabb49dd0464e4827744f

13.5.4

What's New in Aspire 13.5.4

Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.

🐛 Fixes

  • 📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #​20091. (#​20094, backport of #​20092, @​davidfowl)

  • 🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #​18790. (#​19853, backport of #​19230, @​Vladipz)

  • ☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the azure-environment resource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #​19617. (#​19998, backport of #​19843, @​eerhardt)

  • 🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to localhost: URLs, preserving the original library files while still configuring the requested ports. Fixes #​20030. (#​20110, backport of #​20031, @​bart-vmware, @​JamesNK)

  • 🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#​20119, backport of #​19965, @​askpt, @​joperezr)

  • 🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic — IAwsRadiusProviderBuilder and IAzureRadiusProviderBuilder are now marked with ASPIRERADIUS003, matching the existing WithAwsProvider and WithAzureProvider methods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#​19874, @​sebastienros)


Full Changelog: v13.5.3...v13.5.4

Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6

Commits viewable in compare view.

Updated Aspire.Hosting.Testing from 13.5.0 to 13.6.0.

Release notes

Sourced from Aspire.Hosting.Testing's releases.

13.6.0

Aspire 13.6.0

Aspire 13.6 brings persistent application history, a refreshed and more interactive dashboard, first-party Java and Rust hosting, and new Azure deployment options. Coordinated .NET builds, portable volume paths, sharper CLI workflows, and more capable editor tooling make it easier to build, debug, and deploy applications across languages.

Highlights

  • 🗃️ Persistent, refreshed dashboard — SQLite-backed telemetry and resource snapshots let you revisit up to ten application runs, with read-only access to completed runs and default retention limits of 100,000 console log messages, structured logs, and traces each. The dashboard now ships as Native AOT and adopts Fluent UI v5 with a collapsible navigation rail.
  • 🖥️ AppHost-owned terminals and database REPLs — Experimental terminal APIs let AppHosts create interactive sessions in a dashboard dock, dialog, or separate window. Opt-in WithRepl() commands open bundled clients for PostgreSQL, MySQL, MongoDB, SQL Server, Redis, and Valkey, while aspire terminal ps and aspire terminal tape play support discovery and repeatable terminal interactions.
  • 🌐 First-party Java and Rust hosting — New Aspire.Hosting.Java and Aspire.Hosting.Rust packages bring Maven, Gradle, Spring Boot, Quarkus, and Cargo applications into the app model, with generated container builds and VS Code debugging. These integrations build on work that originated in the Aspire Community Toolkit.
  • 🛠️ More flexible AppHosts — The prerelease Aspire.Hosting.Dotnet integration coordinates compatible projects into shared restore and build groups and supports .NET SDK container publishing. Portable volume-path environment variables work across local execution and deployment, while TypeScript AppHosts gain standard appsettings.json configuration and Deno runtime support.
  • ⌨️ Sharper CLI workflows — Select launch profiles with aspire run and aspire start, update repository-local CLI manifests with aspire update, create file-based C# AppHosts with aspire init --language csharp --file-based, and export TypeScript API data with aspire sdk export. Terminal commands no longer need a feature flag, Linux certificate trust includes Firefox NSS databases, and aspire stop --force --volumes adds explicit cleanup of Aspire-owned volumes.
  • 💻 More capable VS Code tooling — Coding agents can start and stop AppHosts through the extension, and the Aspire pane exposes deploy, publish, and pipeline actions. Multi-root discovery, worktree-scoped lifecycle operations, preserved launch arguments, clearer debug logs, and missing-debugger guidance make complex workspaces more predictable.
  • ☁️ New Azure options in preview — Azure Connector Namespace models external-service connections and managed MCP server configurations. Azure Container Apps Sandboxes adds isolated sandbox deployments with configurable resource tiers and lifecycle policies, while Azure Container Apps Express offers a simplified environment option for rapid provisioning.
  • ☸️ More expressive, reliable deployments — Experimental Azure Provisioning SDK proxies let polyglot AppHosts customize infrastructure. Deployment state is isolated under ASPIRE_HOME, Kubernetes preserves inherited hostnames and embedded parameter values, and AKS gains persistent-volume provisioning and more reliable cleanup.
  • 🔌 Expanded integrations — Experimental Deno hosting and MongoDB replica sets join Foundry Toolboxes, remote Foundry Local endpoints, Blazor WebAssembly debugging, and configurable Dev Tunnel expiration. Azure Cosmos DB and AI Inference client integrations gain health checks, and the vNext Cosmos DB emulator sends its own telemetry to the dashboard.

⚠️ Breaking changes

Notable changes include automatic TLS for local MongoDB servers when a certificate is available, the Linux-based vNext Cosmos DB emulator becoming the default, new Azure Front Door origin names that can require cleanup of existing origins, portable connection-string environment-variable aliases on stricter deployment targets, and experimental terminal types moving from Aspire.Hosting.Terminals to Aspire.Hosting.ApplicationModel.

See the full list and migration guidance in the Aspire 13.6 breaking changes.

📖 Learn more

For complete details, examples, migration guidance, and everything new in this release, read What's new in Aspire 13.6.

Thank you to all the community contributors who helped make Aspire 13.6 possible! 💜


Full Changelog: v13.5.4...v13.6.0

Full commit: 56f3e9c0d216c0c7069dabb49dd0464e4827744f

13.5.4

What's New in Aspire 13.5.4

Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.

🐛 Fixes

  • 📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #​20091. (#​20094, backport of #​20092, @​davidfowl)

  • 🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #​18790. (#​19853, backport of #​19230, @​Vladipz)

  • ☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the azure-environment resource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #​19617. (#​19998, backport of #​19843, @​eerhardt)

  • 🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to localhost: URLs, preserving the original library files while still configuring the requested ports. Fixes #​20030. (#​20110, backport of #​20031, @​bart-vmware, @​JamesNK)

  • 🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#​20119, backport of #​19965, @​askpt, @​joperezr)

  • 🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic — IAwsRadiusProviderBuilder and IAzureRadiusProviderBuilder are now marked with ASPIRERADIUS003, matching the existing WithAwsProvider and WithAzureProvider methods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#​19874, @​sebastienros)


Full Changelog: v13.5.3...v13.5.4

Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6

13.5.3

What's New in Aspire 13.5.3

Patch release for Aspire 13.5 that fixes Dashboard Graph view crashes for resources with multi-path icons and restores missing public URLs for DevTunnel resources.

🐛 Fixes

  • 📊 Dashboard Graph view could crash for Azure Blob resources — Resources such as those created with AddBlobs use icons containing multiple SVG paths, which caused an XML parsing exception and broke the dashboard circuit. The graph now combines multi-path icons correctly. Regression introduced in 13.5. Fixes #​19489. (#​19585, backport of #​19579, @​sebastienros)

  • 🌐 DevTunnel public URLs were missing from the Dashboard and MCP snapshots — DevTunnel port resources could report Running and Healthy while showing no public URLs. Proxyless port allocation is now limited to compute and container resources, allowing DevTunnels to publish their actual public endpoints. Regression introduced in 13.5. Fixes #​19496. (#​19625, backport of #​19590, @​karolz-ms, @​danegsta)

🏷️ Housekeeping

  • 🚀 Bumped branding to 13.5.3

Full Changelog: v13.5.2...v13.5.3

Full commit: b5f143315ffb6968ea939a9978797a5b20e4c688

13.5.2

What's New in Aspire 13.5.2

Patch release for Aspire 13.5 that removes an unused native helper binary from the Windows CLI archives so 13.5 servicing releases stay publishable to WinGet.

🐛 Fixes

  • 🪟 Windows CLI archives shipped an unused ~4.9 MB hex1bpty.exe — The Windows CLI archives (aspire-cli-win-{x64,arm64}-*.zip) bundled Hex1b's out-of-process PTY host, which Aspire never executes (DCP owns every pseudo-terminal Aspire surfaces). Besides the wasted download, the extra unexplained executable stalled the WinGet publish, since every binary in the archive goes through executable and malware validation. A build-only MSBuild target now drops the file from the CLI publish output; Unix native assets are unaffected. Regression new in 13.5. ([#​19557]([release/13.5] Exclude unused hex1bpty.exe from published CLI archives microsoft/aspire#19557), backport of #​19554, @​mitchdenny)

🏷️ Housekeeping

  • 🚀 Bumped branding to 13.5.2

Full Changelog: [v13.5.1...v13.5.2](microsoft/aspire@v13.5.1...v13.5.2)

Full commit: [a22cec24d76e764b3681977e314ab4a0aeed0240](microsoft/aspire@a22cec2)

13.5.1

What's New in Aspire 13.5.1

Patch release for Aspire 13.5 fixing a TypeScript/Java polyglot AppHost compatibility regression when running the 13.5 SDK under an older (13.4.x) CLI, plus a DCP update and release-pipeline housekeeping.

🐛 Fixes

  • 🍎 Polyglot AppHosts could crash on startup on macOS — On macOS, polyglot (TypeScript/Python/Java/Go/Rust) AppHosts could crash during startup due to an interaction between how DCP's Go runtime forks detached processes and how .NET Native AOT installs its signal handlers. Updated DCP (Developer Control Plane) to 0.25.13 to resolve the crash. ([#​19528]([release/13.5] [main] Update dependencies from microsoft/dcp microsoft/aspire#19528))

  • 🔗 Polyglot AppHosts on the 13.5 SDK crashed under an older CLI with MissingMethodException — A TypeScript or Java AppHost built with the 13.5 SDK failed to start when launched by an older (13.4.x) CLI, because the newer codegen called Aspire.TypeSystem members that don't exist in the CLI's older contract. Code generation now probes for these additive capabilities before using them, so older CLIs skip only the unsupported feature and startup succeeds. Regression introduced in 13.5 by #​19365. Fixes #​19503. ([#​19524]([release/13.5] Preserve TypeSystem compatibility with older CLIs microsoft/aspire#19524), backport of #​19506, @​adamint)

🏷️ Housekeeping

Full Changelog: [v13.5.0...v13.5.1](microsoft/aspire@v13.5.0...v13.5.1)

Full commit: [69db530a4816698cf1d5fa4557933e0ac4f127c6](microsoft/aspire@69db530)

Commits viewable in compare view.

Updated bunit from 1.40.0 to 2.11.3.

Release notes

Sourced from bunit's releases.

2.11.3

Fixed

  • InvokeOnSpacerBeforeVisible now uses 4 parameters on .NET 11.0. Reported by @​vnbaaij in #​1915. Fixed by @​vnbaaij in #​1919.
  • A JSInterop timeout elapsing while a result was set could crash the test host with InvalidOperationException: Nullable object must have a value. Reported by @​calebcwells in #​1920. Fixed by @​linkdotnet.

2.10.3

Fixed

  • BunitHtmlParser.Dispose() no longer throws InvalidOperationException: Collection was modified when a parse is in flight on another thread during test teardown. Reported by @​thimobuchheister in #​1892. Fixed by @​linkdotnet.

2.9.0

Changed

  • Update to stable package of AngleSharp.Css

2.8.6

Added

  • New overloads to WaitForHelpers to have async assertions and predicates. Reported by @​radmorecameron in #​1833. Fixed by @​linkdotnet.
  • AddAsset to BunitContext to seed the ResourceAssetCollection exposed via ComponentBase.Assets. Reported by LasseHerget in #​1846. Implemented by @​linkdotnet.

2.7.2

Fixed

  • Implemented InvokeConstructorAsync on BunitJSRuntime and BunitJSObjectReference for .NET 10+, which previously threw NotImplementedException. Reported by @​Floopy-Doo in #​1818. Fixed by @​linkdotnet.

2.6.2

Added

  • net11.0 support

2.5.3

Added

  • Render(RenderFragment) is preferred via the OverloadResolutionAttribute. Reported by @​ScarletKuro in #​1800. Fixed by @​linkdotnet.
  • FindByTestId to bunit.web.query to gather elements by a given test id. By @​jimSampica

2.4.2

Fixed

  • Use proper return typed for InputAsync and ChangeAsync methods.

2.3.4

Added

  • Added generic overloads Find{TComponent, TElement} and FindAll{TComponent, TElement} to query for specific element types (e.g., IHtmlInputElement). By @​linkdotnet.
  • Added generic overloads WaitForElement{TComponent, TElement} and WaitForElements{TComponent, TElement} to wait for specific element types. By @​linkdotnet.

Fixed

  • Adding convenient overloads for InputAsync and ChangeAsync to have feature parity with the sync version. Reported by @​ScarletKuro. Fixed by @​linkdotnet.

2.2.2

Added

  • Added FindByAllByLabel to bunit.web.query package. By @​linkdotnet.

Fixed

  • Updated AngleSharp.Diffing to fix a bug related to unknown HTML elements. Reported by @​md-at-slashwhy.

2.1.1

Changed

  • Registering AuthenticationState in the services container rather than as part of the RenderTree. Fixes #​1774 reported by @​aayjaychan.

2.0.66

This major release focuses on platform updates and API simplifications.

For a migration guide, see Upgrading bUnit.

Changed

  • Target framework support updated: added support for .NET 10 (net10.0) and dropped all versions prior to .NET 8 (net8.0).
  • Cleanup of the API with simplifications of many API calls and methods. This also includes renaming of some objects to better reflect their purpose.

Added

  • Support for form submission from submit buttons and inputs that are outside the form element but associated via the HTML5 form attribute. Reported and fixed in #​1766.
  • Improved renderer logic that catches more edge cases.
  • Improved developer experience in relation to JSInterop.

Commits viewable in compare view.

Updated coverlet.collector from 6.0.4 to 10.1.0.

Release notes

Sourced from coverlet.collector's releases.

10.1.0

Improvements

  • Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP #​2019
  • Implement dynamic exclusion filters for assemblies (Coverlet.MTP) #​1946
  • Replace legacy .sln files with modern .slnx format #​1966
  • coverlet.console: add trace diagnostics and actionable warnings for instrumentation/hit/empty-result failures #​2005
  • Relax auto-property skip logic and improve coverage for records #​1941

Fixed

  • Fix coverlet.MTP does not collect coverage on the .NET Framework portion of a large project #​1980 #​1967
  • Fix Regression in branch coverage for lambda expressions #​1938
  • Fix When using "is" with "or" in pattern matching, branch coverage is lower than normal #​1979
  • Fix silent zero coverage on .NET Framework since 8.0.0 #​1985 by @​tobiwae
  • Fix Race condition between ProcessExit hit-file write and out-of-proc coverage read causes EndOfStreamException #​1987 #​1988 by @​bkoelman
  • Fix Regression TypeInitializationException when targeting .NET Framework - Could not load type 'System.Collections.Concurrent.ConcurrentBag #​2010
  • Fix use --config-file CLI arg in coverlet.MTP #​2030 by alexthornton1
  • Fix silently empty coverage for shared-framework assemblies missing from compileLibraries #​2032 by @​Eljees

Diff between 10.0.1 and 10.1.0

10.0.1

Improvements

Fixed

  • Fix inconsistent paths in cobertura reports #​1723
  • Fix when using "is" with "and" in pattern matching, branch coverage is lower than normal #​1313
  • Fix Coverlet flagging a branch for an async functions finally block where none exists #​1337
  • Fix Coverlet Tracker Missing CompilerGeneratedAttribute #​1828

Maintenance

  • Add architecture docs and diagrams for all integrations #​1927
  • Update NuGet packages and .NET SDK versions #​1933

Diff between 10.0.0 and 10.0.1

10.0.0

Improvements

  • Unique Report Filenames (coverlet.MTP and AzDO) #​1866
  • Add --coverlet-file-prefix option for unique report files #​1869
  • Introduce .NET 10 support #​1823

Fixed

  • Fix [BUG] Wrong branch rate on IAsyncEnumerable for generic type #​1836
  • Fix [BUG] Missing Coverage after moving to MTP #​1843
  • Fix [BUG] No coverage reported when targeting .NET Framework with 8.0.1 #​1842
  • Fix [BUG] Behavior changes between MTP and Legacy (msbuild) #​1878
  • Fix [BUG] Coverlet.MTP - Unable to load coverlet.mtp.appsettings.json #​1880
  • Fix [BUG] Coverlet.Collector produces empty report when Mediator.SourceGenerator is referenced #​1718 by https://github.com/yusyd
  • Fix [BUG] Crash during instrumentation (Methods using LibraryImport/DllImport have no body) #​1762

Maintenance

  • Add comprehensive async method tests and documentation for issue #​1864
  • Replace Tmds.ExecFunction Package in coverlet.core.coverage.tests #​1833
  • Add net9.0 and net10.0 targets #​1822

Diff between 8.0.1 and 10.0.0

8.0.1

Fixed

  • Fix [BUG] TypeInitializationException when targeting .NET Framework #​1818
  • Fix [BUG] coverlet.MTP build fails with CS0400 due to developmentDependency=true #​1827

Improvements

  • Additional improvements needed for .NET Framework instrumentation type import #​1825

Diff between 8.0.0 and 8.0.1

8.0.0

Special Thanks: A huge thank you to @​Bertk for driving the majority of the work in this release! 🎉

Fixed

Improvements

  • Coverlet MTP extension feature #​1788
  • Generate SBOM for nuget packages #​1752
  • Use multi targets projects for coverlet.collector, coverlet.msbuild.tasks packages #​1742
  • Use .NET 8.0 target framework for coverlet.core and remove Newtonsoft.Json #​1733
  • Use latest System.CommandLine version #​1660
  • Upgraded minimum required .NET SDK and runtime to .NET 8.0 LTS (Long Term Support) (Breaking Change)
  • Use xunit.v3 for tests and example code

Diff between 6.0.4 and 8.0.0

Commits viewable in compare view.

Updated Meziantou.Analyzer from 3.0.203 to 3.0.291.

Release notes

Sourced from Meziantou.Analyzer's releases.

3.0.291

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.291

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.290...3.0.291

3.0.290

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.290

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.289...3.0.290

3.0.289

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.289

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.288...3.0.289

3.0.288

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.288

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.287...3.0.288

3.0.287

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.287

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.286...3.0.287

3.0.286

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.286

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.285...3.0.286

3.0.285

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.285

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.284...3.0.285

3.0.284

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.284

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.283...3.0.284

3.0.283

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.283

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.282...3.0.283

3.0.282

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.282

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.281...3.0.282

3.0.281

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.281

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.280...3.0.281

3.0.280

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.280

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.279...3.0.280

3.0.279

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.279

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.278...3.0.279

3.0.278

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.278

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.277...3.0.278

3.0.277

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.277

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.276...3.0.277

3.0.276

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.276

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.275...3.0.276

3.0.275

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.275

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.274...3.0.275

3.0.274

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.274

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.273...3.0.274

3.0.273

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.273

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.272...3.0.273

3.0.272

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.272

What's Changed

**Full Changel...

Description has been truncated

Dependabot will resol...

Description has been truncated

Bumps AngleSharp from 1.7.1 to 1.8.3
Bumps Aspire.AppHost.Sdk from 13.5.3 to 13.6.0
Bumps Aspire.Hosting from 13.5.3 to 13.6.0
Bumps Aspire.Hosting.Testing from 13.5.0 to 13.6.0
Bumps bunit from 1.40.0 to 2.11.3
Bumps coverlet.collector from 6.0.4 to 10.1.0
Bumps Meziantou.Analyzer from 3.0.203 to 3.0.291
Bumps Microsoft.Extensions.Configuration.Abstractions from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Configuration.Binder from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.DependencyInjection.Abstractions from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Diagnostics.HealthChecks to 10.0.12
Bumps Microsoft.Extensions.Hosting from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Hosting.Abstractions from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Http.Resilience from 10.9.0 to 10.10.0
Bumps Microsoft.Extensions.Logging.Abstractions from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.ServiceDiscovery from 10.9.0 to 10.10.0
Bumps Microsoft.NET.Test.Sdk from 18.8.1 to 18.10.1
Bumps Microsoft.SourceLink.GitHub from 10.0.400 to 10.0.401
Bumps System.DirectoryServices.Protocols from 10.0.11 to 10.0.12
Bumps xunit.runner.visualstudio from 3.1.5 to 4.0.0

---
updated-dependencies:
- dependency-name: AngleSharp
  dependency-version: 1.8.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-and-aspire
- dependency-name: Aspire.AppHost.Sdk
  dependency-version: 13.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-and-aspire
- dependency-name: Aspire.Hosting
  dependency-version: 13.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-and-aspire
- dependency-name: Aspire.Hosting.Testing
  dependency-version: 13.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-and-aspire
- dependency-name: bunit
  dependency-version: 2.11.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dotnet-and-aspire
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dotnet-and-aspire
- dependency-name: Meziantou.Analyzer
  dependency-version: 3.0.291
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Configuration.Abstractions
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Configuration.Binder
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.DependencyInjection.Abstractions
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Hosting
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Logging.Abstractions
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Hosting.Abstractions
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.SourceLink.GitHub
  dependency-version: 10.0.401
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: System.DirectoryServices.Protocols
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-and-aspire
- dependency-name: xunit.runner.visualstudio
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.Http.Resilience
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-and-aspire
- dependency-name: Microsoft.Extensions.ServiceDiscovery
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-and-aspire
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #187.

@dependabot dependabot Bot closed this Oct 2, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/aspireOpenLdap/Aspire.OpenLdap.Testing/dotnet-and-aspire-638ad28160 branch October 2, 2026 02:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment